PHISHGUARD: A Hybrid GCN-BERT Framework for Context-Aware Social Media Phishing Detection Aligned with MITRE ATT&CK

Authors

  • Karpurapu Rajesh
  • Sagar Imambi

Keywords:

social media phishing, graph convolutional networks, BERT, MITRE ATT&CK, hybrid intelligence, adversarial detection

Abstract

Social media phishing attacks have increased by 72 % globally since 2023, driven by AI-generated lures and coordinated cross-platform campaigns. Traditional detectors based solely on natural language processing or static rules suffer from high false positives and delayed responses. This paper presents PHISHGUARD, a hybrid framework combining graph convolutional networks for user-interaction topology analysis, a fine-tuned BERT model for contextual semantics, and automated MITRE ATT&CK T1598.003 mapping for threat-intelligence alignment. Evaluated on an open-source corpus of 15 000 annotated messages from Twitter/X, Facebook, and Instagram, PHISHGUARD achieves 96.2 % precision, 94.7 % recall, and a 95.4 % F1-score, reducing false positives by 75 % compared to a BERT-only baseline. Ablation studies confirm that both the GCN–BERT fusion layer and threat-context module contribute significantly to performance. The system sustains robust zero-day detection, cuts analyst investigation time by 55 %, and scales to networks of over 10 million users. By unifying semantic, behavioral, and threat-context analysis in an IEEE-aligned structure, PHISHGUARD offers a proactive defense against evolving social-engineering tactics.

Downloads

Published

2025-07-09

How to Cite

Karpurapu Rajesh, & Sagar Imambi. (2025). PHISHGUARD: A Hybrid GCN-BERT Framework for Context-Aware Social Media Phishing Detection Aligned with MITRE ATT&CK. Utilitas Mathematica, 122(1), 1806–1812. Retrieved from http://utilitasmathematica.com/index.php/Index/article/view/2429

Citation Check

Most read articles by the same author(s)

Obs.: This plugin requires at least one statistics/report plugin to be enabled. If your statistics plugins provide more than one metric then please also select a main metric on the admin's site settings page and/or on the journal manager's settings pages.